IM
IronMonkey Threat Research

CVE-2025-71188 MEDIUM

Published: 2026-01-31 | Last Modified: 2026-06-02 | Status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: dmaengine: lpc18xx-dmamux: fix device leak on route allocation Make sure to drop the reference taken when looking up the DMA mux platform device during route allocation. Note that holding a reference to a device does not prevent its driver data from going away so there is no point in keeping the reference.

Additional Descriptions (1)

En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta: dmaengine: lpc18xx-dmamux: corregir fuga de dispositivo en la asignación de ruta Asegúrese de liberar la referencia tomada al buscar el dispositivo de plataforma DMA mux durante la asignación de ruta. Tenga en cuenta que mantener una referencia a un dispositivo no evita que los datos de su controlador desaparezcan, por lo que no tiene sentido mantener la referencia.

CVSS Metrics

Base Score: 5.5 (MEDIUM)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 3.6

Weaknesses

Source Type Description
[email protected] Primary
en CWE-401

Affected Products

Vendor Product Version Update Type
linux linux_kernel * <built-in method update of dict object at 0x7f76011b1700> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7f760079ce00> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7f76027f6680> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7f7638068dc0> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7f76027f7d40> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7f76027f69c0> Operating System
linux linux_kernel 4.3 <built-in method update of dict object at 0x7f7638068f80> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7f7670543780> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7f760079f700> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7f76027f7e80> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7f763806b980> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7f76027f6100> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7f76011b0f40> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7f76003c1700> Operating System
linux linux_kernel 6.19 <built-in method update of dict object at 0x7f763806bdc0> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:4.3:-:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc1:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc4:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc5:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc6:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc7:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.19:rc8:*:*:*:*:*:*

References

Notification
Message here